Re: [Freeipa-devel] [PATCH] Added warning to user for Internet Explorer

2016-04-26 Thread Abhijeet Kasurde
Updated patch attached. On 04/26/2016 09:07 PM, Rob Crittenden wrote: Internet Explorer is no longer a supported browser. From 5a076ee78bc8d779f480f8c6d06c4a74cfad7343 Mon Sep 17 00:00:00 2001 From: Abhijeet Kasurde Date: Mon, 25 Apr 2016 16:23:33 +0530 Subject: [PATCH] Added warning to user

Re: [Freeipa-devel] [DESIGN] Thin client

2016-04-26 Thread Jan Cholasta
On 26.4.2016 18:12, Petr Vobornik wrote: On 04/26/2016 12:28 PM, Jan Cholasta wrote: Hi, see for initial design of the Thin client feature. The API compatibility part of the design is work in progress (by me), as is the client side caching part (by D

[Freeipa-devel] [PATCH 0102] DNS: Fix upgrade - master to forward zone transformatio

2016-04-26 Thread Petr Spacek
Hello, DNS: Fix upgrade - master to forward zone transformation This happens when upgrading from IPA <= 4.0 to versions 4.3+. DNS caching might cause false positive in code which replaces master zone with forward zone. This will effectivelly delete the master zone without adding a replacement fo

Re: [Freeipa-devel] [PATCH] 0001 ipa_kdb add krbPrincipalAuthInd handling

2016-04-26 Thread Matt Rogers
On 04/26, Sumit Bose wrote: > On Thu, Apr 14, 2016 at 12:59:55PM -0400, Matt Rogers wrote: > > > > > > - Original Message - > > > From: "Nathaniel McCallum" > > > To: "Matt Rogers" , freeipa-devel@redhat.com > > > Sent: Thursday, April 14, 2016 10:32:15 AM > > > Subject: Re: [Freeipa-dev

Re: [Freeipa-devel] [DESIGN] Thin client

2016-04-26 Thread Petr Vobornik
On 04/26/2016 12:28 PM, Jan Cholasta wrote: > Hi, > > see for initial design of > the Thin client feature. The API compatibility part of the design is > work in progress (by me), as is the client side caching part (by David). > > Big thanks to David fo

Re: [Freeipa-devel] [PATCH] Added warning to user for Internet Explorer

2016-04-26 Thread Rob Crittenden
Pavel Vomacka wrote: On 04/25/2016 01:00 PM, Abhijeet Kasurde wrote: Hi All, Please review the attached patch. Thanks, Abhijeet Kasurde Hi, thank you for the patch, ACK. I would add an "a" and change it to "Internet Explorer is no longer a supported browser." rob -- Manage your sub

Re: [Freeipa-devel] [PATCH] Added warning to user for Internet Explorer

2016-04-26 Thread Pavel Vomacka
On 04/25/2016 01:00 PM, Abhijeet Kasurde wrote: Hi All, Please review the attached patch. Thanks, Abhijeet Kasurde Hi, thank you for the patch, ACK. -- Pavel^3 Vomacka -- Manage your subscription for the Freeipa-devel mailing list: https://www.redhat.com/mailman/listinfo/freeipa-devel C

Re: [Freeipa-devel] [PATCH] 0018-0030 webui: add support for more certificates

2016-04-26 Thread Pavel Vomacka
Self-NACK for patches 0027, 28, 29, 30 - used incorrect policy. I also attach all patches which were not changed - it is easier to get the whole patchset. On 04/26/2016 02:02 PM, Pavel Vomacka wrote: I forgot to mention that my patches requires patches from : https://www.redhat.com/archives/fr

Re: [Freeipa-devel] URI in HBAC

2016-04-26 Thread Petr Spacek
On 26.4.2016 15:16, Jan Pazdziora wrote: > On Tue, Apr 26, 2016 at 02:16:54PM +0200, Petr Spacek wrote: * For backwards compatibility, lack of URI in request means any URI is matched (as described in the design document). Is it a good idea? Any other solution? >>> >>> For other

[Freeipa-devel] More Python 3 fixes

2016-04-26 Thread Petr Viktorin
Hello, Here are two patches for problems with using IPA with Python 3. -- Petr Viktorin From aad8a7ea093e8aaf0d50f395ff0e0d7038fe55ff Mon Sep 17 00:00:00 2001 From: Petr Viktorin Date: Tue, 26 Apr 2016 14:59:35 +0200 Subject: [PATCH] dns plugin: Fix zone normalization under Python 3 In Python

Re: [Freeipa-devel] URI in HBAC

2016-04-26 Thread Jan Pazdziora
On Tue, Apr 26, 2016 at 02:16:54PM +0200, Petr Spacek wrote: > >> > >> * For backwards compatibility, lack of URI in request means any URI is > >> matched (as described in the design document). Is it a good idea? Any > >> other solution? > > > > For other attributes in HBAC rules, the lack of a va

Re: [Freeipa-devel] [PATCH] 0001 ipa_kdb add krbPrincipalAuthInd handling

2016-04-26 Thread Sumit Bose
On Thu, Apr 14, 2016 at 12:59:55PM -0400, Matt Rogers wrote: > > > - Original Message - > > From: "Nathaniel McCallum" > > To: "Matt Rogers" , freeipa-devel@redhat.com > > Sent: Thursday, April 14, 2016 10:32:15 AM > > Subject: Re: [Freeipa-devel] [PATCH] 0001 ipa_kdb add krbPrincipalAut

Re: [Freeipa-devel] [PATCH 0463] Performance: do not download password attributes in host/find-user command

2016-04-26 Thread Martin Basti
On 22.04.2016 13:21, David Kupka wrote: On 22/04/16 10:58, Martin Basti wrote: On 21.04.2016 09:17, Martin Basti wrote: On 20.04.2016 16:57, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5281 Patch attached. selfNACK Updated patch attached. Works for me, ACK. p

Re: [Freeipa-devel] URI in HBAC

2016-04-26 Thread Petr Spacek
On 26.4.2016 12:57, Jan Cholasta wrote: > Hi, > > On 25.4.2016 14:48, Lukáš Hellebrandt wrote: >> http://www.freeipa.org/page/V4/URI-based_HBAC >> >> I have made some important changes to the design document of this >> proposed feature. The difference is mainly changing regular expression >> inter

Re: [Freeipa-devel] [PATCHES 0464-0468] always set hostname during installation

2016-04-26 Thread Martin Basti
On 26.04.2016 08:32, David Kupka wrote: On 22/04/16 12:48, Martin Basti wrote: On 20.04.2016 17:49, Martin Basti wrote: https://fedorahosted.org/freeipa/ticket/5794 It requires my patch 441.2 Patches attached. Rebased patches attached, 441 has been pushed Martin^2 Thanks for patch

Re: [Freeipa-devel] [PATCH] 0018-0030 webui: add support for more certificates

2016-04-26 Thread Pavel Vomacka
I forgot to mention that my patches requires patches from : https://www.redhat.com/archives/freeipa-devel/2016-April/msg00209.html On 04/26/2016 01:33 PM, Pavel Vomacka wrote: Hello, the attached patches add support for more certificates and ability to add and remove certificates. Fixes these

Re: [Freeipa-devel] [DESIGN] Thin client

2016-04-26 Thread Jan Cholasta
On 26.4.2016 13:26, Petr Spacek wrote: On 26.4.2016 12:28, Jan Cholasta wrote: Hi, see for initial design of the Thin client feature. The API compatibility part of the design is work in progress (by me), as is the client side caching part (by David).

Re: [Freeipa-devel] [PATCH 0439] Do not do extra search for ipasshpubkey

2016-04-26 Thread Martin Basti
On 22.04.2016 15:38, Stanislav Laznicka wrote: Seems to work as expected. Nitpick: feel free to fix the typo in the commit message: behavioar. ACK nonetheless. Standa forgot to sent ACK on list :), please note that ACK is here - Typo fixed Pushed to master: 14ee02dcbd6cbb6c221ac7526

[Freeipa-devel] [PATCH] 0018-0030 webui: add support for more certificates

2016-04-26 Thread Pavel Vomacka
Hello, the attached patches add support for more certificates and ability to add and remove certificates. Fixes these two tickets: https://fedorahosted.org/freeipa/ticket/5108 https://fedorahosted.org/freeipa/ticket/5381 These patches add ability to view, get, download, revoke, restore and de

Re: [Freeipa-devel] [DESIGN] Thin client

2016-04-26 Thread Petr Spacek
On 26.4.2016 12:28, Jan Cholasta wrote: > Hi, > > see for initial design of the > Thin client feature. The API compatibility part of the design is work in > progress (by me), as is the client side caching part (by David). > > Big thanks to David for ac

Re: [Freeipa-devel] URI in HBAC

2016-04-26 Thread Jan Cholasta
Hi, On 25.4.2016 14:48, Lukáš Hellebrandt wrote: http://www.freeipa.org/page/V4/URI-based_HBAC I have made some important changes to the design document of this proposed feature. The difference is mainly changing regular expression interpretation of URI to longest-prefix matching. This change

[Freeipa-devel] [DESIGN] Thin client

2016-04-26 Thread Jan Cholasta
Hi, see for initial design of the Thin client feature. The API compatibility part of the design is work in progress (by me), as is the client side caching part (by David). Big thanks to David for actually writing most of the text in the design pag

Re: [Freeipa-devel] [PATCH 0095-0098] NTP: use augeas, configure chronyd, do not overwrite config

2016-04-26 Thread Petr Spacek
On 26.4.2016 10:09, David Kupka wrote: > diff --git a/ipapython/configfile.py b/ipapython/configfile.py > new file mode 100644 > index > ..b48a9eae97dc4c1b19d6ae7e961ce701a4a36ed7 > --- /dev/null > +++ b/ipapython/configfile.py NACK, I think that Augeas mag

Re: [Freeipa-devel] Possble FreeIPA Trac Malicious Link

2016-04-26 Thread David Kupka
On 25/04/16 15:32, Gabe Alford wrote: Hey all, This is something we may need to watch for. I noticed that a possible malicious link was added to the FreeIPA Trac start page. You can view it here: https://fedorahosted.org/freeipa/wiki/WikiStart?action=diff&version=22. I changed it back to the ori

Re: [Freeipa-devel] [PATCH 0095-0098] NTP: use augeas, configure chronyd, do not overwrite config

2016-04-26 Thread David Kupka
On 14/03/16 14:01, Martin Basti wrote: On 14.03.2016 13:46, Martin Babinsky wrote: On 03/11/2016 09:16 AM, David Kupka wrote: Current version (0.5.0) of python-augeas is missing copy() method. Use dkupka/python-augeas copr repo before new version it's build and available in the official repos

Re: [Freeipa-devel] [PATCH] 0053..0054 Configure lightweight CA key replication

2016-04-26 Thread Jan Cholasta
On 21.4.2016 05:30, Fraser Tweedale wrote: On Thu, Apr 14, 2016 at 04:39:37PM +1000, Fraser Tweedale wrote: Hi all, The attached patches configure lightweight CA key replication on IPA CAs, on upgrade and installation. Patches 0051..0052 from my other mail are also needed for the system to wor

Re: [Freeipa-devel] [PATCH] 0051 Allow CustodiaClient to be used by arbitrary principals

2016-04-26 Thread Jan Cholasta
On 25.4.2016 07:55, Jan Cholasta wrote: Hi, On 20.4.2016 08:22, Fraser Tweedale wrote: On Mon, Apr 18, 2016 at 03:44:08PM -0400, Simo Sorce wrote: On Thu, 2016-04-14 at 16:33 +1000, Fraser Tweedale wrote: On Wed, Apr 13, 2016 at 11:15:50AM +1000, Fraser Tweedale wrote: On Tue, Apr 12, 2016 a